Researchers detailed Linux-focused cryptojacking operations that compromise internet-exposed systems through SSH brute-force attacks and then deploy XMRig to mine Monero. One campaign, tracked as Krane, was first observed through honeypot activity and used Bash scripts, Python tooling, and ELF binaries to establish persistence, erase and recreate logs, kill rival miners and botnets, and move laterally across additional hosts. Krane operators also used subnet and SYN scanning, SSH banner grabbing, and credential attacks to identify new victims, while infected systems reported discovered targets back to command-and-control infrastructure every 15 seconds.
The reporting aligns with broader findings on long-running Linux cryptojacking activity, including the WatchDog campaign, which similarly maintained large-scale miner deployments over an extended period. In Krane, analysts linked delivery infrastructure to multiple download servers and network space associated with AS53667/PONYNET, observed package variants including krax and ssh, and tied mining activity to Hashvault pools and three Monero wallets. At one point, researchers saw more than 200 active miners and estimated proceeds of roughly 2434.26 EUR, underscoring how opportunistic SSH compromise and aggressive competitor removal can sustain profitable, persistent cryptomining operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
CUJO AI reported a previously unseen IoT/Linux malware family named Krane after capturing it in a honeypot. The analysis described SSH brute-force access, Monero mining via XMRig, persistence, log wiping, and lateral propagation tooling.
Palo Alto Networks Unit 42 published research exposing the WatchDog cryptojacking campaign and stated it had been operating for two years. The reference provides no explicit anchored start date for the campaign itself beyond that characterization.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.